Published On: July 07, 2026
Authored By: Suyash Bisht
Graphic Era Hill University Dehradun
Abstract
Artificial intelligence has transformed how people communicate and consume information online, but one of its most troubling applications is deepfake technology, synthetically generated audio, video, or images engineered to closely resemble real people. In India, the misuse of deepfakes has become a pressing legal and social concern in 2025 and into 2026, raising questions about privacy, electoral integrity, and the reliability of digital evidence generally.
I. Introduction
India has seen a growing number of incidents in which deepfakes have been used to deceive the public. Victims have included politicians, journalists, and private individuals, with fabricated videos circulated during election campaigns and used to defraud people or coerce them into sharing private images. These incidents have prompted lawmakers, courts, and regulators to examine whether India’s existing legal framework is equipped to deal with synthetic media, and criminalising the misuse of deepfake content has become a live policy debate.
Deepfake systems use machine learning models to generate convincing facsimiles of faces, voices, and movements. While the same technology has legitimate applications in film production and education, its misuse is what concerns regulators most: deepfakes erode the ability of viewers to distinguish authentic content from fabricated content, which in turn threatens public trust in digital media more broadly. India’s current challenge lies not only in curbing the malicious use of this technology, but also in building a legal architecture that can keep pace with it.
II. Statutory Framework
India does not yet have a standalone deepfake law. Instead, authorities rely on a combination of existing cyber law, criminal law, and data protection statutes: the Information Technology Act, 2000 (IT Act), the Bharatiya Nyaya Sanhita, 2023 (BNS), and the Digital Personal Data Protection Act, 2023 (DPDPA).
1. The Information Technology Act, 2000: Several provisions of the IT Act are routinely used to prosecute deepfake-related conduct. Section 66C penalises identity theft, while Section 66D addresses cheating by personation using a computer resource.[1] Sections 67, 67A, and 67B criminalise the publication or transmission of obscene material, sexually explicit material, and child sexual abuse material in electronic form, respectively, and are frequently invoked where deepfakes are used to create non-consensual explicit content or manipulated intimate imagery.[2]
2. The Bharatiya Nyaya Sanhita, 2023: The BNS, which replaced the Indian Penal Code, contains provisions addressing criminal intimidation, insult, privacy violation, and defamation that are increasingly applied to AI-generated content. Section 356, for instance, criminalises defamation and can be invoked where a deepfake video damages a person’s reputation.[3] Other BNS provisions relating to privacy and harassment are similarly being extended to cover the non-consensual creation or circulation of synthetic media.
3. The Digital Personal Data Protection Act, 2023: Deepfake generation typically depends on unauthorised use of a person’s data, photographs, voice samples, and biometric identifiers. The DPDPA regulates how such personal data may be processed and requires data fiduciaries to obtain valid consent, meaning that the unauthorised use of someone’s likeness to train or generate synthetic media may itself constitute a violation of the Act’s core principles, independent of any downstream misuse.[4]
III. Regulatory Developments
Beyond these general statutes, the Ministry of Electronics and Information Technology (MeitY) has moved to regulate synthetic media directly. In October 2025, MeitY released draft amendments to the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, proposing a formal definition of “synthetically generated information” (SGI) along with mandatory labelling and metadata requirements. Following a stakeholder consultation, MeitY notified the final Amendment Rules on 10 February 2026; they came into force on 20 February 2026.[5]
Under the notified rules, intermediaries that offer tools capable of generating or altering synthetic content must embed a permanent, tamper-resistant label or metadata identifier on their outputs. Significant social media intermediaries, those with more than five million registered users in India, must obtain user declarations on whether uploaded content is synthetically generated, deploy technical measures to verify those declarations, and ensure that confirmed SGI is prominently labelled before it is displayed. The rules also shorten the window for removing unlawful content following a government or court order, and impose an even tighter timeline for content involving non-consensual or morphed intimate imagery.[5] In effect, platforms such as YouTube, Instagram, Facebook, and X are now under binding, not merely proposed, obligations to identify and label deepfake content or risk losing safe-harbour protection.
IV. Open Challenges
1. Definitional and Enforcement Uncertainty: Even with the new SGI definition, no single deepfake-specific offence exists. Lawyers and policymakers continue to note that India’s core criminal and cyber statutes were not originally designed with generative AI in mind, which creates uncertainty about which provision governs a given case and who bears responsibility for a deepfake’s creation versus its distribution. Courts and law enforcement are often left fitting deepfake-related conduct into pre-existing categories such as impersonation, fraud, obscenity, or defamation.
2. Platform Scale and Free Expression Concerns: Because social media platforms can distribute deepfake content at enormous speed and scale, regulators have concentrated on making platforms more accountable for what they host. Civil society groups have cautioned, however, that broadly worded labelling and takedown obligations risk over-labelling legitimate content, including parody, satire, and AI-assisted art, and could, in aggressive enforcement, chill lawful speech.
V. Conclusion
India’s response to deepfakes in 2025 and 2026 illustrates a broader pattern in technology regulation: existing statutes are stretched to cover a problem they were not built for, while more tailored rules, such as MeitY’s newly enforceable SGI labelling regime, are introduced incrementally. Whether this patchwork of the IT Act, the BNS, the DPDPA, and the Intermediary Guidelines proves adequate will depend heavily on enforcement capacity, judicial interpretation, and the extent to which platforms are held to their new verification obligations in practice.
References
[1] Information Technology Act, No. 21 of 2000, §§ 66C, 66D (India).
[2] Information Technology Act, No. 21 of 2000, §§ 67, 67A, 67B (India).
[3] Bharatiya Nyaya Sanhita, No. 45 of 2023, § 356 (India).
[4] Digital Personal Data Protection Act, No. 22 of 2023 (India).
[5] Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026, notified by the Ministry of Electronics and Information Technology (Feb. 10, 2026), in force Feb. 20, 2026.




